Upgrade Path

Gitea 1.7.0 → 1.27.3

146 versions, 29 with breaking changes, 0 required stops

Version by version, oldest first

1.7.1 – 1.7.6: no action items (6 versions)

1.8.0 2019-04-21

Breaking

  • Add "ghost" and "notifications" to list of reserved user names. (#6208)
  • Change sqlite DB path default to data directory (#6198)
  • Adds MustChangePassword to user create/edit API (#6193)
  • Disable redirect for i18n (#5910)
  • Releases API paging (#5831)
  • Allow Macaron to be set to log through to gitea.log (#5667)
  • Don't close issues via commits on non-default branch (#5622)

Full release notes for 1.8.0

1.8.1 – 1.8.3: no action items (3 versions)

1.9.0 2019-07-31

Breaking

  • Better logging (#6038) (#6095)

Full release notes for 1.9.0

1.9.1 2019-08-14

Breaking

  • Add pagination for admin api get orgs and fix only list public orgs bug (#7742) (#7752)

Full release notes for 1.9.1

1.9.2 – 1.9.4: no action items (3 versions)

1.9.5 2019-10-30

Breaking

  • Hide some user information via API if user doesn't have enough permission (#8655) (#8658)

Full release notes for 1.9.5

1.9.6: no action items (1 version)

1.10.0 2019-11-14

Breaking

  • Fix deadline on update issue or PR via API (#8698)
  • Hide some user information via API if user doesn't have enough permission (#8655) (#8657)
  • Remove legacy handling of drone token (#8191)
  • Change repo search to use exact match for topic search. (#7941)
  • Add pagination for admin api get orgs and fix only list public orgs bug (#7742)
  • Implement the ability to change the ssh port to match what is in the gitea config (#7286)

Full release notes for 1.10.0

1.10.1 – 1.10.3: no action items (3 versions)

1.10.4 – 1.10.6: released after 1.11.0; not on this route

1.11.0 2020-02-10

Breaking

  • Fix followers and following tabs in profile (#10202) (#10203)
  • Make CertFile and KeyFile relative to CustomPath (#9868) (#9874)
  • Remove unused endpoints (#9538)
  • Prefix all user-generated IDs in markup (#9477)
  • Enforce Gitea environment for pushes (#8982)
  • Hide some user information via API if user have not enough permissions (#8655)
  • Move startpage/homepage translation to crowdin (#8596)

Full release notes for 1.11.0

1.11.1: no action items (1 version)

1.11.2 2020-03-06

Breaking — from the release blog

Breaking Change: Various fixes in login sources (#10428)

This PR has two major components:

  • A breaking change whereby users from external login sources (eg. PAM and SMTP authentication) will only be autoregistered if the username is valid i.e. [A-Za-z0-9_.-]+.
  • For PAM authentication pam_get_item(PAM_USER) will be called to allow PAM pipelines to adjust the username.

From blog.gitea.com/release-of-1.11.2/

Full release notes for 1.11.2

1.11.3 – 1.12.6: no action items (12 versions; 1.11.8, released after 1.12.0, is not on this route)

1.13.0 2020-12-02

Breaking

  • Set RUN_MODE prod by default (#13765) (#13767)
  • Don't replace underscores in auto-generated IDs in goldmark (#12805)
  • Add Primary Key to Topic and RepoTopic tables (#12639)
  • Disable password complexity check default (#12557)
  • Change PIDFile default from /var/run/gitea.pid to /run/gitea.pid (#12500)
  • Add extension Support to Attachments (allow all types for releases) (#12465)
  • Remove IE11 Support (#11470)

Full release notes for 1.13.0

1.13.1 – 1.13.7: no action items (7 versions)

1.14.0 2021-04-11

Breaking

  • Fix double 'push tag' action feed (#15078) (#15083)
  • Remove possible resource leak (#15067) (#15082)
  • Handle unauthorized user events gracefully (#15071) (#15074)
  • Restore Access.log following migration to Chi framework (Stops access logging of /api/internal routes) (#14475)
  • Migrate from Macaron to Chi framework (#14293)
  • Deprecate building for mips (#14174)
  • Consolidate Logos and update README header (#14136)
  • Inline manifest.json (#14038)
  • Store repository data in data path if not previously set (#13991)
  • Rename "gitea" png to "logo" (#13974)
  • Standardise logging of failed authentication attempts in internal SSH (#13962)
  • Add markdown support in organization description (#13549)
  • Improve users management through the CLI (#6001) (#10492)

Breaking — from the release blog

Breaking Changes (or potentially breaking)

:exclamation: Tag webhooks are now only sent once - you may need to check your CI webhooks to ensure that they are correctly firing. (#15078)

:exclamation: The access logger no longer logs accesses to /api/internal (#14475)

:exclamation: We have migrated from Macaron to the Chi framework. (#14293)

:exclamation: We no longer provide binary builds for MIPS architectures as it appears that they are not being used. (#14174) Instead we now provide binary builds for the M1 architecture. (#14951)

:exclamation: We have improved the mechanism for customizing the default logo (#13974) (#14136)

:exclamation: We now inline the manifest.json - users that expect to see requests for this file should adjust templates as necessary. (#14038)

:exclamation: The default location for repository data ([repository] ROOT) will now be in a subdirectory of the APP_DATA_PATH path. (#13991)

:exclamation: The logging of failed attempts in the internal SSH has been changed to make them a little more consistent. Users with fail2ban set-ups may need to adjust their configuration. (#13962)

:exclamation: Organization descriptions now support markdown. There may be some presentational differences. (#13549)

:exclamation: There has been a few changes of how the CLI for user management works. (#6001) (#10492)

:exclamation: We now default to using a pure Git backend. The Go-Git backend remains in place and can be built using the build tag gogit. (#13673)

:exclamation: We have integrated the environment-to-ini command in to the docker - this allows override of any app.ini setting with specially constructed environment variables. (#14762)

From blog.gitea.com/release-of-1.14.0/

Full release notes for 1.14.0

1.14.1 – 1.14.6: no action items (6 versions)

1.14.7: released after 1.15.0; not on this route

1.15.0 2021-08-22

Breaking

  • Make app.ini permissions more restrictive (#16266)
  • Refactor Webhook + Add X-Hub-Signature (#16176)
  • Add asymmetric JWT signing (#16010)
  • Clean-up the settings hierarchy for issue_indexer queue (#16001)
  • Change default queue settings to be low go-routines (#15964)
  • Improve assets handler middleware (#15961)
  • Rename StaticUrlPrefix to AssetUrlPrefix (#15779)
  • Use a generic markup class to display externally rendered files and diffs (#15735)
  • Add frontend testing, require node 12 (#15315)
  • Move (custom) assets into subpath /assets (#15219)
  • Use level config in log section when sub log section not set level (#15176)
  • Links in markdown should be absolute to the repository not the server (#15088)
  • Upgrade to the latest version of golang-jwt (#16590) (#16606)
  • Set minimum supported version of go to 1.16 (#16710)

Breaking — from the release blog

Breaking Changes (or potentially breaking)

Upgrade to the latest version of golang-jwt and increase minimum go to 1.16 (#16590) (#16606) (#16710)

The minimum version of Go Gitea can be compiled with has been increased to 1.16 as Go 1.14 and Go 1.15 are no longer supported by the go developers.

Changed mapping of :latest on docker #16421

The docker tag logic has changed to map :latest to match the latest tag on the 1.15 branch and :dev to represent the latest build on the main branch. Users who wish to use the development version of Gitea - with all its latest features should switch to use the :dev tag for docker. We would like to encourage at least some users to consider using :dev.

More restrictive app.ini permissions #16266

The default file permissions mode for app.ini has changed to -rw------- when Gitea creates this file.

Webhook Refactors #16176

Webhook payloads have been changed so that the Secret field is no longer passed as part of the payload and the history shows the real URL that was sent in the webhook.

Asymmetric JWT Signing Key #16010

We have added asymmetric JWT signing and Gitea will use an asymmetric keypair for JWT signing by default.

  • Asymmetric algorithms require a secret asymmetric key pair to be in JWT_SIGNING_PRIVATE_KEY_FILE (by default APP_DATA_PATH/jwt), a pair will be generated if it is not present. (NB: this was originally in CUSTOM_PATH but was changed by #16227)
  • The original symmetric JWT_SECRET will only be used if JWT_SIGNING_ALGORITHM is set to HS256 (previous default), HS384 or HS512.
  • As a result of the change of algorithm gitea OAuth2 tokens (and potentially the client secret) will need to be regenerated unless you change your JWT_SIGNING_ALGORITHM back to HS256.
  • Legacy installations of Drone assume a short key length, however as no automated migrations are run by Drone you'll need to do them manually if the column type for user_oauth_token and user_oauth_refresh are limited to 500 characters.
-- an example manual migration for Drone database connected to postgresql
alter table users alter column user_oauth_token type bytea using convert_to(user_oauth_token, 'LATIN1');
alter table users alter column user_oauth_refresh type bytea using convert_to(user_oauth_refresh, 'LATIN1');

Clean-up the settings hierarchy for issue_indexer queue #16001

We have changed the priority of settings below:

  • [queue.issue_indexer] TYPE now overrides [indexers] ISSUE_INDEXER_QUEUE_TYPE
  • [queue.issue_indexer] DATADIR overrides [indexers] ISSUE_INDEXER_QUEUE_DIR
  • [queue.issue_indexer] CONN_STR overrides [indexers] ISSUE_INDEXER_QUEUE_CONN_STR
  • [queue.issue_indexer] BATCH_LENGTH overrides [indexers] ISSUE_INDEXER_QUEUE_BATCH_NUMBER
  • [queue.issue_indexer] LENGTH overrides [indexers] UPDATE_BUFFER_LEN

It is not expected that many people will experience effects from this change.

Change default queue settings to be low go-routines #15964

We have changed the default configuration for queues to make them low goroutines by default:

  • As a result of this PR instead of each queue having their own level db by default, the queues will use a common level db. It is recommended to ensure that queues are empty before upgrading using gitea manager flush-queues or on the admin pages.
  • Starting workers are now 0 with boost workers at 1. If you have explicitly set BOOST_WORKERS = 0 you will need to explicitly set WORKERS to at least 1. Administrators of busy sites should tune their WORKERS, BOOST_WORKERS, & DATADIR parameters as needed.

Merged assets handler middleware #15961

This PR merges two assets handler middleware as one and move it before session middleware to reduce unnecessary memory usage. The additional support for CORS on assets may cause some breakage for sites using CDN assets. Administrators should change [cors] section in the app.ini to add the domains if enabled.

Rename StaticUrlPrefix to AssetUrlPrefix #15779

This PR renames the template variable StaticUrlPrefix to AssetUrlPrefix. Administrators with Custom templates that use the StaticUrlPrefix will need update these to use AssetUrlPrefix.

Use markup class for rendering External markup #15735

This PR essentially changes the markdown css class to markup. Administrators with css/less customization targeting the .markdown class should update these to use .markup.

Update Node to v12 #15315

This PR increases the minimum required node version for compiling the frontend to v12.

Add /assets as root dir of public files #15219

This PR moves root directory of public files from / to /assets.

All pages and resources rendered from custom/public will now be rendered at /assets instead of /. This means that if you have a impressum.html - you need to update links to this to /assets/impressum.html. Similarly for users of STL renderers and external markup renderers.

Administrators should check custom templates to ensure that these are correct.

If you have previously placed robots.txt within custom/public you must move it to custom instead.

Inherit log level in sub log section #15176

Sub loggers will inherit their log level from the main log level - previously these would default to info. Administrators should check their log configuration.

Make links in markdown absolute to the repository not the server #15088

This PR changes the rendering of links in markdown to make them absolute to the current repository in keeping with Github. This may change rendering of some pages however, the previous behaviour was not compatible with Github so was a bug.

From blog.gitea.com/release-of-1.15.0/

Full release notes for 1.15.0

1.15.1 – 1.15.11: no action items (11 versions)

1.16.0 2022-01-30

Breaking

  • Remove golang vendored directory (#18277)
  • Paginate releases page & set default page size to 10 (#16857)
  • Only allow webhook to send requests to allowed hosts (#17482)

Breaking — from the release blog

Breaking Changes (or potentially breaking)

Only allow webhook to send requests to allowed hosts (#17482)

For security reasons, the webhook should only send requests to allowed hosts.

This PR introduced ALLOWED_HOST_LIST with default value of external meaning that Webhooks by default can only call external hosts for security reasons.

Although ALLOWED_HOST_LIST was backported to 1.15 the default value is different between 1.15 and 1.16 and is more strict. If you need to allow Webhooks to call local network hosts you must explicitly allow those IPs/Hosts.

Remove golang vendored directory (#18277)

We no longer store the vendored directory within git. Users building directly from git checkouts should run make vendor on pulls or when changing branches.

Paginate releases page & set default page size to 10 (#16857)

We have reduced the number of releases shown on the releases page from 30 to 10 and add paging.

Users may change the default value by setting

[repository.release]
DEFAULT_PAGING_NUM=10

Use shadowing script for docker (#17846)

Too many docker users are caught out by the default location for the app.ini file being environment dependent so that when they docker exec into the container the gitea commands do not work properly and require additional -c arguments to correctly pick up the configuration.

This PR simply shadows the gitea binary using variants of the FHS compatible script to make the command gitea have the default locations by default.

Although this PR should be non-breaking for most configurations and should make things simpler for docker users in general, there was a slightly unforeseen issue in that SSH passthrough configurations that rely on the path of the gitea binary being /app/gitea/gitea will need to update this to /usr/local/bin/gitea (likely including moving their host shim from /app/gitea/gitea to /usr/local/bin/gitea)

Users should use /usr/local/bin/gitea in preference to /app/gitea/gitea when executing on the docker as this will automatically set the correct paths and environment for them.

Support webauthn (#17957)

U2F support has been deprecated by major browsers and therefore we've had to migrate to WebAuthn. We've attempted to create a backwards compatible migration however, the website relying party ID used for webauthentication is not the same as that used by U2F.

In order to support old u2f keys previously registered Gitea will use the app_id extension and will send the contents of [U2F] APP_ID as this app_id. This will need to match your original u2f configuration.

From blog.gitea.com/release-of-1.16.0-and-1.16.1/

Full release notes for 1.16.0

1.16.1 – 1.16.3: no action items (3 versions)

1.16.4 2022-03-14

Quoted from blog.gitea.com/release-of-1.16.4/

Breaking — from the release blog

Breaking Change: Refactor mirror code & fix StartToMirror (#19075)

This PR will make old queue entrys unredable for the new version, make sure to flush the mirror sync queue before updating.

Breaking — from the release blog

Breaking Change: Restrict email address validation (#19085)

Narrow the allowed chars a email address can have.

Breaking — from the release blog

Breaking Change: Add pam account authorization check (#18904)

Users of the PAM module who rely on account modules not being checked will need to change their PAM configuration.

Full release notes for 1.16.4

1.16.5 2022-03-24

Breaking — from the release blog

Breaking Change: Bump to build with go1.18 (#19120 et al) (#19127)

Go 1.18 has been released and with its release 1.16 has been deprecated. In order to be able to build with 1.18 several packages have had to be updated. This PR collates these together and changes our build process to build with 1.18.

From blog.gitea.com/release-of-1.16.5/

Full release notes for 1.16.5

1.16.6 – 1.16.9: no action items (4 versions)

1.17.0 2022-07-30

Breaking

  • Require go1.18 for Gitea 1.17 (#19918)
  • Make AppDataPath absolute against the AppWorkPath if it is not (#19815)
  • Nuke the incorrect permission report on /api/v1/notifications (#19761)
  • Refactor git module, make Gitea use internal git config (#19732)
  • Remove RequireHighlightJS field, update plantuml example. (#19615)
  • Increase minimal required git version to 2.0 (#19577)
  • Add a directory prefix gitea-src-VERSION to release-tar-file (#19396)
  • Use "main" as default branch name (#19354)
  • Make cron task no notice on success (#19221)
  • Add pam account authorization check (#19040)
  • Show messages for users if the ROOT_URL is wrong, show JavaScript errors (#18971)
  • Refactor mirror code & fix StartToMirror (#18904)
  • Remove deprecated SSH ciphers from default (#18697)
  • Add the possibility to allow the user to have a favicon which differs from the main logo (#18542)
  • Update reserved usernames list (#18438)
  • Support custom ACME provider (#18340)
  • Change initial TrustModel to committer (#18335)
  • Update HTTP status codes (#18063)
  • Upgrade Alpine from 3.13 to 3.15 (#18050)
  • Restrict email address validation (#17688)
  • Refactor Router Logger (#17308)

Breaking — from the release blog

Internal Gitconfig (#19732)

Previously, Gitea used the users gitconfig ($HOME/.gitconfig) in addition to the system gitconfig (/etc/gitconfig). Now, Gitea uses the system gitconfig (/etc/gitconfig) combined with an internal gitconfig located in {[git].HOME_PATH}/.gitconfig. If you customized your user gitconfig for Gitea, you should add these customizations to one of the available gitconfigs. Additional git-relevant files that are normally in your user home directory, like $HOME/.gnupg, should be moved/ copied to {[git].HOME_PATH}/ as well.

Email address validation restricted (#17688)

With this release, Gitea restricts what is seen as a valid email: Emails must only contain characters in a-zA-Z0-9.!#$%&'*+-/=?^_{|}`~. Additionally, the first letter must be in a-zA-Z0-9, and after the @, only characters in a-zA-Z0-9. can follow.

Renamed configuration options for ACME / Let's Encrypt (#18340)

Configuration settings have been renamed from LETSENCRYPT to ACME. The old settings are deprecated and will be removed in 1.18, you should migrate now.

  • ENABLE_LETSENCRYPT → ENABLE_ACME
  • LETSENCRYPT_URL → ACME_URL
  • LETSENCRYPT_ACCEPTTOS → ACME_ACCEPTTOS
  • LETSENCRYPT_DIRECTORY → ACME_DIRECTORY
  • LETSENCRYPT_EMAIL → ACME_EMAIL

New logger format and configuration (#17308)

This PR substantially changes the logging format of the router logger. If you use this logging for monitoring (e.g. fail2ban) you will need to update this to match the new format. Refer to the documentation on the router logger for new configuration options.

main as default branch (#19354)

The default value of the setting repository.DEFAULT_BRANCH was switched from master to main. If you want to continue using master as default branch name, set this setting. This change is especially relevant for third party tools that assume the default branch of a repository.

Change initial trust model to committer (#18335)

Previously, Gitea would by default use the collaborator trust model. This means only verified commits of collaborators can be trusted. This was quite an aggressive trust model, and now it has changed to match GitHub's behavior of trusting the commiter. This means verified commits in a repository from non-collaborators won't be marked as unverified.

If you rely on the old behavior, you must set DEFAULT_TRUST_MODEL to collaborator.

Require Git >= 2.0 (#19577)

The minimal required Git version has been raised to 2.0. Versions below that are now unsupported and will prevent the application from starting. In general, it is recommended to stay up-to-date with your Git version as some Gitea features or optimizations can only be used once they are available in Git.

Require docker version >= 20.10.6 (#18050)

This is due to an issue with libc of the new base image alpine 3.15.

Require Go >= 1.18 to compile (#19918, #19099)

The minimum version of Go needed to compile Gitea has been increased to 1.18.

Changed handling of custom logo (#18542)

It is now not only possible to set a custom logo, but also a custom favicon. If you are currently using a custom logo, you need to re-run the steps described here.

RequireHighlightJS removed from templates (#19615)

If you use custom templates, check that they do not use RequireHighlightJS anymore as this was outdated already and has now been removed.

Reserved usernames updated (#18438)

The following usernames are now newly reserved: avatar, ssh_info, and swagger_v1.json. The following usernames are no longer reserved: help, install, less, plugins, stars, and template.

If you want to check if you're affected, please run the following Gitea doctor command:

gitea doctor --run check-user-names

Note that this command is only available after upgrading to 1.17.1.

Deprecated SSH ciphers removed from default setting (#18697)

This only affects Gitea instances that have enabled the internal SSH server. Previously, Gitea allowed unsecured algorithms to be used for an SSH connection. Older versions of OpenSSH might not be able to connect to Gitea anymore.

Display messages for users if the ROOT_URL is wrong, show JavaScript errors (#18971)

Previously, Gitea would allow an incorrect ROOT_URL to be set in the settings. This caused unexpected issues when people don't use that URL to visit Gitea. Therefore, Gitea will now show an error in the UI when this is the case. Please check if your ROOT_URL is set correctly and avoid accessing the instance using other URLs to avoid the error message.

/api/v1/notifications does not include repo permissions (#19761)

Previously, /api/v1/notifications returned repository.permissions but the permissions were calculated incorrectly. Due to this and the fact that there exists another route to get the repo permissions, this field will always be null from now on.

HTTP status codes updated: 302 → 307 and 301 → 308 (#18063)

Previously, Gitea often returned the incorrect status codes Found (302) and Moved Permanently (301). All occurrences of such status code were now changed to Temporary Redirect (307) and Permanent Redirect (308) respectively.

No more admin notice about successful cron tasks (#19221)

Successful cron task no longer emit a notification by default. This breaks NO_SUCCESS_NOTICE settings. If you want notices on success, you must set NOTICE_ON_SUCCESS=true.

From blog.gitea.com/release-of-1.17.0/

Full release notes for 1.17.0

1.17.1: no action items (1 version)

1.17.2 2022-09-06

Breaking — from the release blog

After release we discovered that a template function removal was backported, which may break user templates. (#20932)

Users may need to update their custom templates to stop using this function.

From blog.gitea.com/release-of-1.17.2/

Full release notes for 1.17.2

1.17.3 – 1.17.4: no action items (2 versions)

1.18.0 2022-12-29

Breaking

  • Rework mailer settings (#18982)
  • Remove U2F support (#20141)
  • Refactor i18n to locale (#20153)
  • Enable contenthash in filename for dynamic assets (#20813)

Breaking — from the release blog

Remove ReverseProxy authentication from the API (#22219)

Access to the API was removed for ReverseProxy authentication. Users will now be required to use tokens or basic auth.

Mailing: Rework mailer settings (#18982)

  • If you specify credentials for sending emails but the server doesn't support using them, Gitea will fail to start instead of sending mails unauthenticated.
  • Use unique mailer.PROTOCOL for different mailers (SMTP family, sendmail, dummy), instead of MAILER_TYPE+PROTOCOL.
  • The combined mailer.HOST option has been deprecated in favor of the new mailer.SMTP_ADDR and mailer.SMTP_PORT options.
  • The mailer.IS_TLS_ENABLED option has been deprecated in favor of using the new mailer.PROTOCOL option, which accepts smtp, smtps, smtp+startls, or smtp+unix explicitly. If you don't know what protocol your provider uses but provide a port, you can leave it blank and it will be inferred by the given port. See the non-breaking changes section for more details on the new smtp+unix protocol.
  • The mailer.DISABLE_HELO (default false) option has been replaced with mailer.ENABLE_HELO (default true). It still does the same thing, but the option was negated to be less confusing.
  • The mailer.SKIP_VERIFY option has been replaced with mailer.FORCE_TRUST_SERVER_CERT to sound scarier, and to clarify what it does.
  • The mailer.USE_CERTIFICATE, mailer.CERT_FILE, and mailer.KEY_FILE have been deprecated and renamed to mailer.USE_CLIENT_CERT, mailer.CLIENT_CERT_FILE, and mailer.CLIENT_KEY_FILE.

Some configuration moved from config file to database (#18058)

Two configurations, picture.DISABLE_GRAVATAR and picture.ENABLE_FEDERATED_AVATAR, have been copied to database config setting table so that admins can change them in the admin panel without restarting the gitea service. The existing config settings in app.ini will be migrated to the database on first run after upgrading, then the database settings will take precedence.

Authentication: Remove U2F support (#20141)

Gitea 1.18 completelely removes U2F support. Users should migrate to webauthn if they haven't already.

Templates: Refactor i18n to locale (#20153)

Any user with custom templates will be affected by this and will need to replace .i18n with .locale.

Templates: Remove MD5 function (#20813)

The MD5 function was removed due being insecure, and due to being unused with the new approach. Any user with custom templates will be affected by this and will need to remove any occurrence of the MD5 function.


From blog.gitea.com/release-of-1.18.0/

Full release notes for 1.18.0

1.18.1 – 1.18.5: no action items (5 versions)

1.19.0 2023-03-20

Breaking

  • Add loading yaml label template files (#22976) (#23232)
  • Make issue and code search support camel case for Bleve (#22829)
  • Repositories: by default disable all units except code and pulls on forks (#22541)
  • Support template for merge message description (#22248)
  • Remove ONLY_SHOW_RELEVANT_REPOS setting (#21962)
  • Implement actions (#21937)
  • Remove deprecated DSA host key from Docker Container (#21522)
  • Improve valid user name check (#20136)

Breaking — from the release blog

Incorrectly documented default value for update checker (#22084)

[cron.update_checker].ENABLED is true by default. Previously, the documentation indicated that it would be disabled by default, which was incorrect.

Newly reserved username: gitea-actions (#21937)

With the implementation of Gitea Actions (see below), Gitea needed a user to run the actions. The username gitea-actions was chosen and is thus now reserved. If a user with that name exists, an admin should rename them, i.e. using the admin panel.

Remove DSA host key from Docker Container (#21522)

The DSA host key has been removed from the OpenSSH daemon configuration file in the Docker container for Gitea. This change is a result of the deprecation of the DSA public key algorithm since OpenSSH >= 7.0. As a result, any client that uses DSA for authentication will no longer be able to connect to the Docker container. We recommend users to use a different public key algorithm such as RSA or ECDSA for authentication.

Remove ReverseProxy authentication from the API (#22219)

ReverseProxy-authentication was an insecure way of authenticating a user. Hence, it was dropped without replacement. Any user that relied on it must switch to basic or token authentication now.

Remove [ui].ONLY_SHOW_RELEVANT_REPOS setting. (#21962)

On the explore page, you can switch whether you only want to see relevant repos, or all repos. As this page already offers a link to switch between these two options, this setting only had a negligible effect and complicated the logic by a lot. Hence, it was dropped without replacement. You can now remove it from your app.ini if present.

Restrict valid user names (#20136)

Valid user names now follow the following rules:

  • allowed letters are -,., _, 0-9, a-z, A-Z
  • names must not start or end with -,., or _
  • names must not have consecutive -,., or _. (i.e. a-.b is illegal)

No action must be taken for existing users. This is only enforced for newly created users.

Separate allowed units for normal repos and forks (#22541)

Previously, fork repositories had all default units. Now, forks only enable code access and pull requests by default. If you want everything to behave like before, please set the setting [repository].DEFAULT_FORK_REPO_UNITS to the value of [repository].DEFAULT_REPO_UNITS.

Support camel case for issue and code search when using Bleve (#22829)

In order to be able to support queries that include camel case tokens, the indexes must be rebuilt. This is an automatic process that will be done on the first startup without any user interaction.

Support commit description in the merge template (#22248)

Previously, your whole default_merge_message template file was considered to be the commit title. Now, only the first line is the commit title, and the rest (from line 3 on) is the commit description, just like in normal commits.

From blog.gitea.com/release-of-1.19.0/

Full release notes for 1.19.0

1.19.1 2023-04-13

Breaking

  • Rename actions unit to repo.actions and add docs for it (#23733) (#23881)

Full release notes for 1.19.1

1.19.2 – 1.19.4: no action items (3 versions)

1.20.0 2023-07-16

Breaking

  • Fix WORK_DIR for docker (root) image (#25738) (#25811)
  • Restrict [actions].DEFAULT_ACTIONS_URL to only github or self (#25581) (#25604)
  • Refactor path & config system (#25330) (#25416)
  • Fix all possible setting error related storages and added some tests (#23911) (#25244)
  • Use a separate admin page to show global stats, remove actions stat (#25062)
  • Remove the service worker (#25010)
  • Remove meta tags theme-color and default-theme (#24960)
  • Use [git.config] for reflog cleaning up (#24958)
  • Allow all URL schemes in Markdown links by default (#24805)
  • Redesign Scoped Access Tokens (#24767)
  • Fix team members API endpoint pagination (#24754)
  • Rewrite logger system (#24726)
  • Increase default LFS auth timeout from 20m to 24h (#24628)
  • Rewrite queue (#24505)
  • Remove unused setting time.FORMAT (#24430)
  • Refactor setting.Other and remove unused SHOW_FOOTER_BRANDING (#24270)
  • Correct the access log format (#24085)
  • Reserve ".png" suffix for user/org names (#23992)
  • Prefer native parser for SSH public key parsing (#23798)
  • Editor preview support for external renderers (#23333)
  • Add Gitea Profile Readmes (#23260)
  • Refactor ctx in templates (#23105)

Breaking — from the release blog

Refactored scoped tokens mechanism (#24767)

As will be described down below in more detail, the permissions for Personal Access Tokens (PATs) have changed. While we have migrated all old tokens to the new format as close as possible, there are edge cases where an old token now has more/less permissions than before as the two systems have a completely different design. If that's the case for you, please consider regenerating your token to prevent API calls from failing or your token having a too broad scope.

Removed/changed config entries (#25010, #24958, #24754, #24628, #24505, #24430, #24270, #23798, #23733, #23333, #25604)

  • We've removed the service worker functionality as it didn't bring any noticeable benefit, mostly added bugs, and was disabled since 1.17 by default already.

Removed config key: [ui].USE_SERVICE_WORKER

  • The default value of [server].LFS_HTTP_AUTH_EXPIRY has been increased from 20m to 24h.

If you want to use the previous value, please set the setting.

  • As will be described below, you can now set any git config also in your app.ini.

As such, we removed the section [git.reflog] and its keys have been moved to the following replacements:

  • [git.reflog].ENABLED → [git.config].core.logAllRefUpdates
  • [git.reflog].EXPIRATION → [git.config].gc.reflogExpire
  • In addition to the already deprecated options inside [queue], many options have been dropped as well.

Those are WRAP_IF_NECESSARY, MAX_ATTEMPTS, TIMEOUT, WORKERS, BLOCK_TIMEOUT, BOOST_TIMEOUT, BOOST_WORKERS. You can remove them from your app.ini now. Additionally, some default values have changed in this section.

  • The setting [time].FORMAT is no longer used
  • The setting [other].SHOW_FOOTER_BRANDING was removed, as its intended purpose was superseded by [other].SHOW_FOOTER_VERSION
  • The default value of [server].SSH_KEYGEN_PATH has changed from ssh-keygen to (empty), meaning that Gitea parses public keys by default itself rather than passing it to the system as previously.
  • [repository].DEFAULT_REPO_UNITS and [repository].DISABLED_REPO_UNITS accepted the key actions.actions for a short time.

However, the correct key should be repo.actions.

  • [repository.editor].PREVIEWABLE_FILE_MODES was buggy and didn't work.

As such, it is now removed.

  • [actions].DEFAULT_ACTIONS_URL could previously be set to any custom URLs like https://gitea.com or http://your-git-server, and the default value was https://gitea.com. But now, DEFAULT_ACTIONS_URL only supports github (https://github.com) or self (the root url of current Gitea instance), and the default value is github. This change was made to make action names globally resolvable in most cases.

Publication of README.md in .profile repos (#23260)

As will be discussed below in the new features, Gitea now displays user profile READMEs. The displayed content is that of the README.md of a .profile repo. If you already have a repo with that name, its README.md will be publically accessible, even if the repo is private. If you don't want to leak that information, consider renaming your existing repo.

Any URL scheme may be used for links (#24805)

Previously, we would not render non-standard URLs (like matrix:) by default. We allowed adding custom URLs by modifying markdown.CUSTOM_URL_SCHEMES and these would then render as links in markdown, but there was no option to allow all schemes.

With this change in place, if markdown.CUSTOM_URL_SCHEMES is not configured, we will render all explicit markdown links ([label](URL)) as links.

Before

The matrix: and cbthunderlink:// didn't render as links.

[image: Special links are not rendered]

After

The matrix: and cbthunderlink:// render as links, when we use the [label](URL) form.

[image: Special links are rendered]

Newly reserved usernames (#23992)

User and organization names can no longer end with .png.

Changed access log format (#24085)

Logs from the access logger were previously escaped in unnecessary places. Now, they no longer are. Furthermore, the field {{.Ctx.RemoteAddr}} has been renamed to {{.Ctx.RemoteHost}} to omit the port.

Correct pagination in API route teams/{id}/members (#24754)

Previously, this endpoint was 0-based paginated unlike all other routes. This bug has now been fixed.

Refactored path and config system (#25416)

The Gitea path system has been fairly complicated for a long time: It tried to guess paths quite often, which lead to countless problems. Instead, Gitea now automatically tries to store the path inside the config. If it fails to do so, it won't start. In that case, please do what the error message in the logs tells you to do and the issue should be resolved.

actions table metrics collector was removed (#25062)

The statistic of how many entries are in the actions table that records activities has always been rather useless as this table will always be (ridiculuously) large. As such, we removed the metrics collector for promethues for them. Please do not rely on its output anymore. This is not related to Gitea Actions.

Rework storage settings (#23911)

All storage settings should be stored in one section, and one section only. You cannot use multiple sections anymore to override settings. The storage settings priority is now

  1. [attachment]
  2. [storage.attachments] | [storage.<another>]
  3. [storage]
  4. default

For extra override configuration items, currently only are SERVE_DIRECT, MINIO_BASE_PATH, MINIO_BUCKET, which could be configured in another section. The prioioty of the override configuration is [attachment] > [storage.attachments] > default.

Refactor ctx in templates (#23105)

If you use custom templates, you may need to change them: We've changed all occurring .ctx inside parameters to .ctxData. Any custom template currently using .ctx will need to follow suit.

Rewrite logger system (#24726)

The log.<mode>.<logger> style config has been dropped. If you used it, please check the new config manual & app.example.ini to make your instance output logs as expected.

The SMTP logger is deleted because SMTP is not suitable to collect logs.

From blog.gitea.com/release-of-1.20.0/

Full release notes for 1.20.0

1.20.1 – 1.20.2: no action items (2 versions)

1.20.3 2023-08-20

Breaking

  • Fix the wrong derive path (#26271) (#26318)

Breaking — from the release blog

In #23912, we missed that PATH can be inherited from its parent sections. This means that if admins define a global [storage].PATH configuration and don't override it in subsections (i.e. [storage.lfs].PATH), all data will be stored exactly in this PATH without any attachments, lfs, … subfolders. In other words, files can be overwritten unintentionally. Fortunately, most instances will not be affected by this.

With #26271, this is now fixed. However, we cannot migrate existing data into subfolders. Please check your configuration. If you notice that you set [storage].PATH but not the concrete child section paths, please move the files into the respective default subfolders as detailed in the documentation. Additionally, you can think about explicitly setting the concrete storage PATHs or unsetting [storage].PATH.

From blog.gitea.com/release-of-1.20.3/

Full release notes for 1.20.3

1.20.4 – 1.20.5: no action items (2 versions)

1.20.6: released after 1.21.0; not on this route

1.21.0 2023-11-14

Breaking

  • Restrict certificate type for builtin SSH server (#26789)
  • Refactor to use urfave/cli/v2 (#25959)
  • Move public asset files to the proper directory (#25907)
  • Remove commit status running and warning to align GitHub (#25839) (partially reverted: Restore warning commit status (#27504) (#27529))
  • Remove "CHARSET" config option for MySQL, always use "utf8mb4" (#25413)
  • Set SSH_AUTHORIZED_KEYS_BACKUP to false (#25412)

Breaking — from the release blog

These changes are likely to affect the way Gitea works for at least some users. These changes are sorted by importance, with the top ones likely requiring some actions from you, and the bottom ones mostly not affecting anyone.

⚠️ Move public asset files to the proper directory (#25907)

At some point, a folder structure emerged for Gitea where files stored in custom/public/* have been served under https://gitea.example.com/assets/*, which lead to a lot of confusion for new users trying to customize their instances. To correct this behavior, we changed the default assets folder to custom/public/assets/*.

If you have custom asset files, e. g. custom themes, inside custom/public/*, you need to transfer these files to custom/public/assets/* for them to be detected by Gitea v1.21.

⚠️ Set SSH_AUTHORIZED_KEYS_BACKUP to false (#25412)

Previously, the configuration option [server].SSH_AUTHORIZED_KEYS_BACKUP, which makes Gitea automatically create backups of the authorized_keys file every time a new SSH key is added by a user, was set to true by default. However, this lead to the backup folder getting enormously large on instances with many users.

As a consequence, we decided to change the default value of this parameter to false. Please ensure to set it to true manually inside your app.ini if you want for Gitea to continue creating backups of this file.

⚠️ Remove CHARSET config option for MySQL, always use utf8mb4 (#25413)

Using utf8 as a charset for MySQL may result in issues, e. g. with emoji characters, however a new installation can still end up using it through the [database].CHARSET configuration option. The superior utf8mb4 character set is being supported since MySQL v5.5, and as Gitea only supports MySQL v5.7+, support for utf8 is no longer needed in Gitea. To eliminate such issues, we decided to remove this configuration option completely.

Existing utf8 databases will continue to work without modifications, however we strongly recommend you to convert them to utf8mb4 using the gitea doctor convert command.

⚠️ Refactor Gitea cli (#25959)

A refactoring of Gitea's cli package lead to some changes in the way it treats command options:

  • gitea without subcommands no longer accepts gitea web options.
  • --install-port, --pid, --port, --quiet, and --verbose belong to the web sub-command
  • use ./gitea web --pid … instead
  • ./gitea can still run the web sub-command as shorthand, with default options
  • The sub-command's options must follow the sub-command
  • before: ./gitea --sub-opt subcmd might equal to ./gitea subcmd --sub-opt
  • after: only ./gitea subcmd --sub-opt can be used
  • global options like --config are not affected

⚠️ Restrict certificate type for builtin SSH server (#26789)

When using certificate authentication, the OpenSSH server automatically rejects host certificates which are being used as client certificates. Similarly to OpenSSH, Gitea's built-in SSH server now also requires you to use proper client certificates when connecting. Most users should be unaffected by this change.

⚠️ Remove commit status running to align with GitHub (#25839)

When implementing Gitea Actions, the additional commit status "running" was introduced in Gitea v1.19, which resulted in partially confusing aggregated commit status behavior if compared to GitHub. We decided to remove "running" with this release to simplify the commit status and make it more consistent with GitHub.

From blog.gitea.com/release-of-1.21.0/

Full release notes for 1.21.0

1.21.1 – 1.21.11: no action items (11 versions)

1.22.0 2024-05-27

Breaking

  • Improve reverse proxy documents and clarify the AppURL guessing behavior (#31003) (#31020)
  • Remember log in for a month by default (#30150)
  • Breaking summary for template refactoring (#29395)
  • All custom templates need to follow these changes
  • Recommend/convert to use case-sensitive collation for MySQL/MSSQL (#28662)
  • Make offline mode as default to not connect external avatar service by default (#28548)
  • Include public repos in the doer's dashboard for issue search (#28304)
  • Use restricted sanitizer for repository description (#28141)
  • Support storage base path as prefix (#27827)
  • Enhanced auth token / remember me (#27606)
  • Rename the default themes to gitea-light, gitea-dark, gitea-auto (#27419)
  • If you didn't see the new themes, please remove the [ui].THEMES config option from app.ini
  • Require MySQL 8.0, PostgreSQL 12, MSSQL 2012 (#27337)

Breaking — from the release blog

Increased DB requirements (#27337)

Gitea only officially supports DBs that have not reached EOL. There are many database versions that have reached End of Life.

As such, we have increased the DB requirements as follows:

  • MySQL 5.7 → MySQL 8.0
  • PostgreSQL 10 → PostgreSQL 12
  • MSSQL 2008 → MSSQL 2012

Caution

Support for MySQL 5.7, PostgreSQL 10/11, and MSSQL 2008 is dropped. You are encouraged to upgrade to supported versions.

If you have to use an unsupported database version, please get in touch with us for information on our Extended Support Contracts. We can provide testing and support for older databases and integrate those fixes into the Gitea codebase.

MySQL/MSSQL DBs should be case sensitive (#28662)

MySQL (including MariaDB) and MSSQL create databases case-insensitively by default, meaning for example that gitea is equal to GITea.

Historically, this led to many bug reports of functionality behaving unexpectedly, i.e. branches not being able to be inserted because a new branch only differed in casing compared to an existing branch. Gitea was never intended to be used in a case-insensitive DB.

Now, Gitea will explicitly warn you if it detects being run in a case-insensitive DB. If you haven't done so already, please convert your DB to a case-sensitive one.

Note

Postgres and SQLite users are most likely unaffected as those DBs are already case-sensitive by default.

Breaking summary for template refactoring (#29395)

The template system has been refactored, and some template functions may have been changed or removed.

  • Safe is renamed to SafeHTML, and in most cases it shouldn't be used.
  • Escape is renamed to HTMLEscape, and in most cases it shouldn't be used. The template should escape most variables automatically.
  • Str2html is renamed to SanitizeHTML, only use it when necessary, it only "sanitizes" the input by pre-defined rules, but it doesn't "render" or "convert" the content.
  • Use HTMLFormat instead of printf when processing HTML-related contents.

Caution

If you use custom templates (either for the UI or for emails), please read through #29395 to ensure your custom templates will work again.

Default theme change (#27419)

Gitea simplified its theme naming in this release.

The available themes are now gitea-light (previously gitea), gitea-dark (previously arc-green), gitea-auto (previously auto).

This has multiple effects:

  • If you have any custom themes named like that, please rename them to continue using them.
  • It is now possible to check which theme is active by querying the attribute

html[data-theme] instead of the previous html.theme-<theme> when expressing the query as a CSS selector. This change is especially important for third-party tooling whose behavior depends on which theme is active.

  • If you set [ui].DEFAULT_THEME previously, you need to change it to the new theme name.

If you see a black-and-white UI after the update, it is likely that you need to update this setting as the theme cannot be found.

Changed markdown highlighting syntax (#29121)

As we will explain in more detail in the new features, Gitea is now capable of additional alert types using a new syntax.

At the same time, the old syntax > **Note** A note/> **Warning** A warning has been removed, so please rewrite your existing markdown documents to the new syntax where applicable.

If you used:

> **Note** My note

or

> **Warning** My warning

Rewrite these as:

> [!NOTE]
> My note

or

> [!WARNING]
> My warning

Only minimal markdown allowed in repo descriptions (#28141)

Previously, the repository description accepted any sort of markdown. Now, you can only use basic markdown features such as bold, italic, or highlighted text.

Breaking API changes (#27153, #28339)

There were two minor breaking changes to the API in this release:

  • Previously, the push mirror API returned timestamps in an incorrect format. This has now been updated to behave exactly like any other timestamp.
  • The already deprecated (and due to a bug, unusable) pagination parameter per_page has been removed from the list releases endpoint. Instead, you should use the limit parameter.

Login is now remembered for a month by default (#30150)

Previously, your login was only remembered for a week by default. However, many instances don't set the setting and have no explicit security requirements, so having such a short interval is not user-friendly.

If your instance requires a high level of security, you may want to set

[security]
// highlight-next-line
LOGIN_REMEMBER_DAYS = 7

or something similar again.

Removed configurations (#27606, #28527)

Some settings are no longer used. If you previously set any of them, you can now safely remove them from your config:

  • ~~[security].COOKIE_USERNAME~~
  • ~~[cache].ENABLED~~
  • ~~[cache.last_commit].ENABLED~~

Caution

Caches are now enabled by default and cannot be disabled. The default adapter is memory, you can change it to redis, etc. More details are in https://docs.gitea.com/administration/config-cheat-sheet#cache-cache

Support storage base path as prefix (#27827)

This PR will affect all configurations having base_path in the storage section but no base_path in the derived storage configuration sections. The base_path on [storage] will become a prefix for them but will not share the same base_path.

[storage]
; Now it becomes a prefix of derived base_path but not share the name
// highlight-next-line
base_path = xxx 

No Gravatar by default (#28548)

The default value of [server].OFFLINE_MODE has been changed to true, so Gitea will not allow Gravatar queries by default.

However, most existing instances won't be affected by this, as this setting is only used as the default value for the Gravatar settings, not the actual value.

Additionally, it is saved into the config when you install Gitea.

From blog.gitea.com/release-of-1.22.0/

Full release notes for 1.22.0

1.22.1 – 1.22.6: no action items (6 versions)

1.23.0 2025-01-09

Breaking

  • Rename config option [camo].Allways to [camo].Always (#32097)
  • Remove SHA1 for support for SSH RSA signing (#31857)
  • Use UTC as the default timezone when scheduling Actions cron tasks (#31742)
  • Delete Actions logs older than 1 year by default (#31735)
  • Make OIDC introspection authentication strictly require Client ID and secret (#31632)

Breaking — from the release blog

Actions logs expired will be cleaned up in background. (#31735)

A new configuration [actions].LOG_RETENTION_DAYS = 365 was introduced to control how long the logs should be deleted. The default value is 365 days. If you want to keep the logs longer, you need to change the configurations once you upgrade.

Configuration [camo].Allways was corrected to [camo].Always (#32097)

The configuration setting [camo].Allways contained a typo and has been corrected to [camo].Always. Users should update their configuration files to reflect this change to ensure compatibility with the latest version. This adjustment improves clarity and prevents potential misconfigurations caused by the incorrect spelling.

Make OIDC introspection authentication strictly require Client ID and secret (#31632)

OIDC introspection authentication now strictly requires a Client ID and secret, enhancing security. Update your configuration to ensure compatibility.

Remove SHA1 for support for ssh rsa signing (#31857)

Support for SHA1 in SSH RSA signing has been removed due to security concerns. Users should ensure their environments and keys are updated to use more secure algorithms.

Use UTC as default timezone when schedule Actions cron tasks (#31742)

Actions cron tasks now default to UTC for scheduling, ensuring consistency across environments. If the server's local time zone is not UTC, a scheduled task would run at a different time after upgrading Gitea to this version.

Administration URL changed from /admin to /-/admin to allow accounts named admin. (#32189) This maybe a break change for those instances which have customized site header.

The administration URL has been updated to /-/admin to allow accounts named admin. This change may affect instances with customized site headers. Update your configurations or customizations accordingly to prevent disruptions.

From blog.gitea.com/release-of-1.23.0/

Full release notes for 1.23.0

1.23.1: no action items (1 version)

1.23.2 2025-02-05

Breaking

  • Add tests for webhook and fix some webhook bugs (#33396) (#33442)
  • Package webhook’s Organization was incorrectly used as the User struct. This PR fixes the issue.
  • This changelog is just a hint. The change is not really breaking because most fields are the same, most users are not affected.

Full release notes for 1.23.2

1.23.3 – 1.23.8: no action items (6 versions)

1.24.0 2025-06-10

Breaking

  • Make Gitea always use its internal config, ignore /etc/gitconfig (#33076)
  • Improve log format (#33814)
  • Fix markdown render behaviors (#34122)
  • Add package version api endpoints (#34173)

Breaking — from the release blog

Make Gitea always use its internal config, ignore /etc/gitconfig (#33076)

Historically, Gitea has been able to use the system config under /etc/gitconfig to support some edge-case customizations. However, it sometimes causes conflicts, which have arisen multiple times lately. Therefore, we decided to switch away from this practice, adding GIT_CONFIG_NOSYSTEM=1 to all git commands.

If you have made changes to /etc/gitconfig to affect Gitea's behavior, you need to move these config options to Gitea's internal git config file, it is usually in Gitea's {AppDataPath}/home/.gitconfig.

Thank you to @wxiaoguang for contributing this feature.

Improve log format (#33814)

The router log format was changed from

2025/03/06 22:21:12 ...eb/routing/logger.go:102:func1() [I] router: completed GET / for [::1]:52693, 200 OK in 15.9ms @ web/home.go:32(web.Home)

to

2025/03/06 22:20:35 HTTPRequest [I] router: completed GET / for [::1]:52631, 200 OK in 7.5ms @ web/home.go:32(web.Home)

Thank you to @wxiaoguang for contributing this feature.

Fix markdown render behaviors (#34122)

Add config options MATH_CODE_BLOCK_DETECTION, problematic syntaxes are disabled by default.

Some markdown rendering behaviors are improved to match GitHub, please refer to the latest document's "Markdown" page to see the details.

Thank you to @wxiaoguang for contributing this feature.

Add package version api endpoints (#34173)

Two new API endpoints to list versions of a package and to get the latest version of a package were added.

The size field for this endpoint changes case from Size to size for consistency.

Thank you to @KN4CK3R for contributing this feature.

From blog.gitea.com/release-of-1.24.0/

Full release notes for 1.24.0

1.24.1 – 1.24.7: no action items (7 versions)

1.25.0 2025-10-29

Breaking

  • Return 201 Created for CreateVariable API responses (#34517)
  • Add label 'state' to metric 'gitea_users' (#34326)

Breaking — from the release blog

Remove deprecated auth sources (#35272)

Deprecated authentication sources have been removed in this version. Please ensure your authentication configuration is up to date before upgrading.

Refactor and update mail templates (#35150)

Mail templates have been refactored to improve maintainability. If you have customized mail templates, please note that this is a breaking change.

Thank you to @techknowlogick for contributing this feature.

From blog.gitea.com/release-of-1.25.0/

Full release notes for 1.25.0

1.25.1 – 1.25.5: no action items (5 versions)

1.26.0 2026-04-18

Breaking

  • Correct swagger annotations for enums, status codes, and notification state (#37030)
  • Remove GET API registration-token (#36801)
  • Support Actions concurrency syntax (#32751)
  • Make PUBLIC_URL_DETECTION default to "auto" (#36955)

Breaking — from the release blog

Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)

The standalone environment-to-ini tool was removed and a sub command of gitea has been introduced. If you need to re-create the configuration file with only a subset of keys, you can provide an INI template file and use the "--config-keep-keys" flag.

Correct Swagger annotations for enums, status codes, and notification state (#37030)

The generated OpenAPI description is now aligned with the actual API: enum values, HTTP status codes, and notification state are documented more accurately. If you rely on the published Swagger spec for code generation or contract tests, regenerate clients and re-check any assumptions about optional fields or response shapes.

Thank you to @myers for contributing this change.

Remove GET API registration-token (#36801)

The GET endpoint used to retrieve a registration token has been removed. Automation that still calls it needs to be updated to the supported registration flow for your deployment.

Thank you to @lunny for contributing this change.

Support Actions concurrency syntax (#32751)

Workflows can now use GitHub-style concurrency groups so that new runs cancel or queue relative to in-progress jobs. That changes runtime behavior compared with earlier releases, so review existing workflows after upgrading—especially long-running or overlapping pipelines.

Thank you to @Zettat123 for contributing this feature.

Make PUBLIC_URL_DETECTION default to auto (#36955)

New installations now default to automatic public URL detection. If you depend on a specific explicit URL configuration behind reverse proxies or alternate hostnames, confirm your [server] settings after upgrade so links, webhooks, and redirects still match your environment.

Thank you to @wxiaoguang for contributing this change.

From blog.gitea.com/release-of-1.26.0/

Full release notes for 1.26.0

1.26.1 – 1.26.2: no action items (2 versions)

1.26.3 2026-06-20

Warning

Please upgrade to 1.26.4 directly. A regression in this release can cause "context deadline exceeded" errors when opening any repository's code pages (#38177). Please hold off on upgrading until a fix is released.

Breaking

  • fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041)

Breaking — from the release blog

This release tightens the fork pull request approval gate: a pull request from a fork must now be merged before it can bypass the approval gate (#38041). Review your workflow approval settings if you rely on the previous behavior.

From blog.gitea.com/release-of-1.26.3-and-1.26.4/

Full release notes for 1.26.3

1.26.4: no action items (1 version)

1.27.0 2026-07-13

Breaking

  • Feat(actions)!: improve support for reusable workflows (#37478)
  • Use Content-Security-Policy: script nonce (#37232)

Breaking — from the release blog

Move release artifact signing to sigstore (#38250)

Gitea release artifacts are now signed with sigstore instead of the previous GPG flow. If you verify downloaded binaries or Docker images as part of your deployment pipeline, update your verification step to the sigstore-based process.

Thank you to @TheFox0x7 for contributing this change.

Improve support for reusable workflows (#37478)

Reusable workflows referenced with uses: are now parsed on the Gitea side rather than on the runner. Each called (child) job is inserted as its own ActionRunJob and dispatched as an independent task, so callee logs surface as separate job entries instead of being inlined into the caller's "Set up job" step. Review workflows that rely on reusable-workflow behavior after upgrading.

External reusable workflows (uses: https://other-gitea-instance/OWNER/REPO/.gitea/workflows/test.yaml@REF) are no longer supported. To keep using them, clone the repositories to the local instance and reference them there.

Thank you to @Zettat123 for contributing this change.

Use a Content-Security-Policy script nonce (#37232)

Inline scripts are now allowed via a per-request CSP nonce instead of a broader policy. Custom templates, themes, or embeds that inject inline <script> tags may stop executing until they are updated to carry the nonce. Review custom front-end customizations after upgrading.

Thank you to @wxiaoguang for contributing this change.

X-Content-Type-Options: nosniff is now sent by default (#37354)

All responses now include the X-Content-Type-Options: nosniff header, which stops browsers from MIME-sniffing responses away from their declared Content-Type. If a reverse proxy, embed, or custom asset relied on content sniffing, set X_CONTENT_TYPE_OPTIONS = unset under [security] to remove the header, or override its value as needed.

Thank you to @SAY-5 for contributing this change.

From blog.gitea.com/release-of-1.27.0/

Full release notes for 1.27.0

1.27.1 – 1.27.3: no action items (3 versions)

Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.